2009-07-22 09:46:24 +00:00
|
|
|
#!/bin/sh
|
|
|
|
|
2013-07-05 04:21:13 +00:00
|
|
|
# abuild-keygen - generate signing keys
|
2009-07-22 09:46:24 +00:00
|
|
|
# Copyright (c) 2009 Natanael Copa <ncopa@alpinelinux.org>
|
|
|
|
#
|
|
|
|
# Distributed under GPL-2
|
|
|
|
#
|
|
|
|
|
|
|
|
abuild_ver=@VERSION@
|
2013-07-05 04:21:16 +00:00
|
|
|
datadir=@datadir@
|
2009-07-22 09:46:24 +00:00
|
|
|
|
2013-07-05 04:21:16 +00:00
|
|
|
if ! [ -f "$datadir/functions.sh" ]; then
|
|
|
|
echo "$datadir/functions.sh: not found" >&2
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
. "$datadir/functions.sh"
|
2009-07-22 09:46:24 +00:00
|
|
|
|
2010-12-20 13:33:45 +00:00
|
|
|
|
2010-12-20 13:22:29 +00:00
|
|
|
# ask for privkey unless non-interactive mode
|
|
|
|
# returns value in global $privkey
|
|
|
|
get_privkey_file() {
|
2013-07-05 04:21:20 +00:00
|
|
|
local emailaddr default_name
|
2013-07-05 04:21:14 +00:00
|
|
|
emailaddr=${PACKAGER##*<}
|
|
|
|
emailaddr=${emailaddr%%>*}
|
|
|
|
|
|
|
|
# if PACKAGER does not contain a valid email address, then ask git
|
|
|
|
if [ -z "$emailaddr" ] || [ "${emailaddr##*@}" = "$emailaddr" ]; then
|
|
|
|
emailaddr=$(git config --get user.email 2>/dev/null)
|
|
|
|
fi
|
|
|
|
|
2013-07-05 04:21:20 +00:00
|
|
|
default_name="${emailaddr:-$USER}-$(printf "%x" $(date +%s))"
|
2013-07-05 04:21:14 +00:00
|
|
|
|
2013-07-05 04:21:39 +00:00
|
|
|
privkey="$ABUILD_USERDIR/$default_name.rsa"
|
2013-07-05 04:21:20 +00:00
|
|
|
[ -n "$non_interactive" ] && return 0
|
2013-07-05 04:21:37 +00:00
|
|
|
msg "Generating public/private rsa key pair for abuild"
|
2013-07-05 04:21:20 +00:00
|
|
|
echo -n "Enter file in which to save the key [$privkey]: "
|
2010-12-20 13:22:29 +00:00
|
|
|
|
|
|
|
read line
|
|
|
|
if [ -n "$line" ]; then
|
|
|
|
privkey="$line"
|
|
|
|
fi
|
|
|
|
}
|
2009-07-22 14:16:58 +00:00
|
|
|
|
2013-07-05 04:21:14 +00:00
|
|
|
do_keygen() {
|
2013-07-05 04:21:39 +00:00
|
|
|
mkdir -p "$ABUILD_USERDIR"
|
2013-07-05 04:21:14 +00:00
|
|
|
|
|
|
|
get_privkey_file
|
|
|
|
pubkey="$privkey.pub"
|
|
|
|
|
|
|
|
# generate the private key in a subshell with stricter umask
|
|
|
|
(
|
|
|
|
umask 0007
|
|
|
|
openssl genrsa -out "$privkey" 2048
|
|
|
|
)
|
|
|
|
openssl rsa -in "$privkey" -pubout -out "$pubkey"
|
|
|
|
|
|
|
|
|
|
|
|
if [ -n "$install_pubkey" ]; then
|
|
|
|
msg "Installing $pubkey to /etc/apk/keys..."
|
|
|
|
sudo mkdir -p /etc/apk/keys
|
|
|
|
sudo cp -i "$pubkey" /etc/apk/keys/
|
|
|
|
else
|
|
|
|
|
|
|
|
msg ""
|
|
|
|
msg "You'll need to install $pubkey into "
|
|
|
|
msg "/etc/apk/keys to be able to install packages and repositories signed with"
|
|
|
|
msg "$privkey"
|
|
|
|
fi
|
|
|
|
|
|
|
|
if [ -n "$append_config" ]; then
|
2013-07-05 04:21:39 +00:00
|
|
|
if [ -f "$ABUILD_USERCONF" ]; then
|
2013-07-05 04:21:14 +00:00
|
|
|
# comment out the existing values
|
2013-07-05 04:21:39 +00:00
|
|
|
sed -i -e 's/^PACKAGER_PRIVKEY=/\#&/' "$ABUILD_USERCONF"
|
2013-07-05 04:21:14 +00:00
|
|
|
fi
|
2013-07-05 04:21:39 +00:00
|
|
|
echo "PACKAGER_PRIVKEY=\"$privkey\"" >> "$ABUILD_USERCONF"
|
2013-07-05 04:21:14 +00:00
|
|
|
else
|
|
|
|
msg ""
|
2013-07-05 04:21:39 +00:00
|
|
|
msg "You might want add following line to $ABUILD_USERCONF:"
|
2013-07-05 04:21:14 +00:00
|
|
|
msg ""
|
|
|
|
msg "PACKAGER_PRIVKEY=\"$privkey\""
|
|
|
|
msg ""
|
|
|
|
fi
|
|
|
|
|
|
|
|
msg ""
|
|
|
|
msg "Please remember to make a safe backup of your private key:"
|
|
|
|
msg "$privkey"
|
|
|
|
msg ""
|
|
|
|
}
|
|
|
|
|
2009-07-22 14:16:58 +00:00
|
|
|
usage() {
|
2013-07-05 04:21:19 +00:00
|
|
|
cat >&2 <<__EOF__
|
|
|
|
$prog $abuild_ver - generate signing keys
|
|
|
|
Usage: $prog [-a|--append] [-i|--install] [-n]
|
|
|
|
Options:
|
2013-07-05 04:21:39 +00:00
|
|
|
-a, --append Set PACKAGER_PRIVKEY=<generated key> in $ABUILD_USERCONF
|
2013-07-05 04:21:19 +00:00
|
|
|
-i, --install Install public key into /etc/apk/keys using sudo
|
|
|
|
-n Non-interactive. Use defaults
|
|
|
|
-q, --quiet
|
|
|
|
-h, --help Show this help
|
|
|
|
|
|
|
|
__EOF__
|
2009-07-22 14:16:58 +00:00
|
|
|
}
|
|
|
|
|
2013-07-05 04:21:19 +00:00
|
|
|
append_config=
|
|
|
|
install_pubkey=
|
|
|
|
non_interactive=
|
|
|
|
quiet=
|
2009-07-22 09:46:24 +00:00
|
|
|
|
2013-07-05 04:21:19 +00:00
|
|
|
args=`getopt -o ainqh --long append,install,quiet,help -n "$prog" -- "$@"`
|
|
|
|
if [ $? -ne 0 ]; then
|
|
|
|
usage
|
|
|
|
exit 2
|
|
|
|
fi
|
|
|
|
eval set -- "$args"
|
|
|
|
while true; do
|
|
|
|
case $1 in
|
|
|
|
-a|--append) append_config=1;;
|
|
|
|
-i|--install) install_pubkey=1;;
|
2013-07-05 04:21:20 +00:00
|
|
|
-n) non_interactive=1;;
|
2013-07-05 04:21:19 +00:00
|
|
|
-q|--quiet) quiet=1;; # suppresses msg
|
|
|
|
-h|--help) usage; exit;;
|
|
|
|
--) shift; break;;
|
|
|
|
*) exit 1;; # getopt error
|
2009-07-22 14:16:58 +00:00
|
|
|
esac
|
2013-07-05 04:21:19 +00:00
|
|
|
shift
|
2009-07-22 14:16:58 +00:00
|
|
|
done
|
2013-07-05 04:21:19 +00:00
|
|
|
if [ $# -ne 0 ]; then
|
|
|
|
usage
|
|
|
|
exit 2
|
|
|
|
fi
|
2009-07-22 14:16:58 +00:00
|
|
|
|
2013-07-05 04:21:14 +00:00
|
|
|
do_keygen
|